CVE-2024-7079 is a medium-severity vulnerability affecting Red Hat OpenShift Container Platform, where an unauthenticated user can access the /API/helm/verify endpoint due to a flaw in the authentication middleware. This allows remote attackers to potentially gain high confidentiality impact by fetching and verifying Helm charts without proper authorization. While the CVSS score is 6.5, indicating a medium risk, there is currently no public exploit code available, and it has not been observed in active exploitation or garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.11CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.